Anonymous
2026-09-22 01:45:42
(2 days ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 01:42:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:42:14.611390 2026] [security2:error] [pid 21606:tid 21606] [client 34.21.239.88:59624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.flic.net"] [uri "/.git/config"] [unique_id "arHc9nelNtE8n25np7vwHwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-22 01:09:39
(2 days ago)
AetherFox VoidGuard detected: [Tue Sep 22 03:09:39.068100 2026] [authz_core:error] [pid 494252:tid 4 ...
show more
AetherFox VoidGuard detected: [Tue Sep 22 03:09:39.068100 2026] [authz_core:error] [pid 494252:tid 494295] [client 34.21.239.88:34530] AH01630: client denied by server configuration: proxy:https://136.243.123.86/
[Tue Sep 22 03:09:39.068317 2026] [authz_core:error] [pid 494252:tid 494295] [client 34.21.239.88:34530] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Tue Sep 22 03:09:39.234819 2026] [authz_core:error] [pid 494252:tid 494283] [client 34.21.239.88:34530] AH01630: client denied by server configuration: proxy:https://136.243.123.86/ssl/localhost.key
[Tue Sep 22 03:09:39.235030 2026] [authz_core:error] [pid 494252:tid 494283] [client 34.21.239.88:34530] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Tue Sep 22 03:09:39.394245 2026] [authz_core:error] [pid 494252:tid 494302] [client 34.21.239.88:34530] AH01630: client denied by server configuration: proxy:https://136.243.123.86/.bash_profile
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:09:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:09:19.754928 2026] [security2:error] [pid 4094:tid 4094] [client 34.21.239.88:36118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bizzmail.net"] [uri "/config/.env"] [unique_id "arHVPxxXiIL3FMXu3Kmn9AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-22 00:51:15
(2 days ago)
Domain : acrelifts.net
Rule : UserAgent
2026-09-22 00:49:44 W3SVC29 PLESK76 217.194.212.111 GET /env ...
show more
Domain : acrelifts.net
Rule : UserAgent
2026-09-22 00:49:44 W3SVC29 PLESK76 217.194.212.111 GET /env.json - 443 - 34.21.239.88 HTTP/2.0 Mozilla/5.0 (compatible; Baiduspider/2.0; http://www.baidu.com/search/spider.html) - - www.acrelifts.net 404 0 0 6594 407 269 - -
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 00:45:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:45:47.515566 2026] [security2:error] [pid 25209:tid 25209] [client 34.21.239.88:36110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyberclay.net"] [uri "/.env"] [unique_id "arHPuyaXBFjuOw0NvAwYjAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-22 00:08:58
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /__/firebase/init.json
Timestamp: 2026-09-21T22:08:14Z
Ray ID: a3ec6328fa708209
UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)
show less
Bad Web Bot
๐ธ๐ช
EmK530
2026-09-21 23:30:13
(2 days ago)
URL flagged by RegEx: /build../.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:50:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:50:51.086177 2026] [security2:error] [pid 32459:tid 32459] [client 34.21.239.88:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.assistguide.net"] [uri "/.env.backup"] [unique_id "arG0y4THf2DNXLXEsAnkIgAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:28:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:28:21.110813 2026] [security2:error] [pid 25367:tid 25367] [client 34.21.239.88:60078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advantage-plus.net"] [uri "/frontend/.env"] [unique_id "arGvhS7w0-zPOjNBocxC5AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-21 22:06:23
(2 days ago)
200 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 21:49:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:49:48.737030 2026] [security2:error] [pid 24460:tid 24460] [client 34.21.239.88:57408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davidsonmanagement.net"] [uri "/.git/config"] [unique_id "arGmfKbV80t4bh_lPtPOGwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:22:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.88 (88.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:22:37.506724 2026] [security2:error] [pid 8517:tid 8534] [client 34.21.239.88:60422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.agriclean.net"] [uri "/web/.env"] [unique_id "arGgHWe8CTWTIbhP1u4JvAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 21:13:10
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
regishoussin
2026-09-21 21:03:23
(2 days ago)
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-21 21:03 UTC.
show less
Bad Web Bot
Web App Attack